a-foo-module
Advanced tools
Comparing version 1.0.0 to 1.0.1
{ | ||
"name": "a-foo-module", | ||
"version": "1.0.0", | ||
"version": "1.0.1", | ||
"description": "a foo module", | ||
@@ -19,4 +19,4 @@ "main": "index.js", | ||
"dependencies": { | ||
"opossum": "git://github.com/nodeshift/opossum.git" | ||
"a-bar-module": "^1.0.0" | ||
} | ||
} |
Git dependency
Supply chain riskContains a dependency which resolves to a remote git URL. Dependencies fetched from git URLs are not immutable and can be used to inject untrusted code or reduce the likelihood of a reproducible install.
Found 1 instance in 1 package
0
1653
+ Addeda-bar-module@^1.0.0
+ Addeda-bar-module@1.0.0(transitive)